Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.400exploits catalogados
37.193CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
CA eSCC r8/1.0 / eTrust Audit r8/1.5 - Arbitrary File Manipulation
CVE-2006-4900remotewindows21 sep 2006
Directory traversal vulnerability in Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, a
23RIESGO
abrir
Exploit-DBVexDay Proof
BandSite CMS 1.1 - 'login_header.php' Cross-Site Scripting
CVE-2006-4985webappsphp21 sep 2006
Multiple cross-site scripting (XSS) vulnerabilities in Grayscale BandSite CMS allow remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
NeoSys Neon Webmail for Java 5.06/5.07 - 'updateuser?in_name' Servlet Cross-Site Scripting
CVE-2006-4956webappsjsp20 sep 2006
Cross-site scripting (XSS) vulnerability in the updateuser servlet in Neon WebMail for Java before 5.08 allows remote at
23RIESGO
abrir
Exploit-DBVexDay Proof
NeoSys Neon Webmail for Java 5.06/5.07 - 'addrlist' Servlet Multiple SQL Injections
CVE-2006-4953webappsjsp20 sep 2006
Multiple SQL injection vulnerabilities in Neon WebMail for Java before 5.08 allow remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
NeoSys Neon Webmail for Java 5.06/5.07 - 'updatemail' Servlet Arbitrary Mail Message Manipulation
CVE-2006-4952webappsjsp20 sep 2006
The updatemail servlet in Neon WebMail for Java before 5.08 allows remote attackers to move e-mail messages of arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
NeoSys Neon Webmail for Java 5.06/5.07 - 'updateuser?in_id' Servlet Arbitrary User Information Modification
CVE-2006-4954webappsjsp20 sep 2006
The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote a
23RIESGO
abrir
Exploit-DBVexDay Proof
NeoSys Neon Webmail for Java 5.06/5.07 - 'downloadfile' Servlet Traversal Arbitrary File Access
CVE-2006-4955webappsjsp20 sep 2006
Directory traversal vulnerability in the downloadfile servlet in Neon WebMail for Java before 5.08 allows remote attacke
23RIESGO
abrir
Exploit-DBVexDay Proof
NeoSys Neon Webmail for Java 5.06/5.07 - 'maillist' Servlet Multiple SQL Injections
CVE-2006-4953webappsjsp20 sep 2006
Multiple SQL injection vulnerabilities in Neon WebMail for Java before 5.08 allow remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Dr.Web AntiVirus 4.33 - LHA long Directory name Local Overflow
CVE-2006-4438locallinux20 sep 2006
Heap-based buffer overflow in SpIDer for Dr.Web Scanner for Linux 4.33, and possibly earlier versions, allows remote att
28RIESGO
abrir
Exploit-DBVexDay Proof
ESyndiCat 1.5 - 'search.php' Cross-Site Scripting
CVE-2006-4923webappsphp19 sep 2006
Cross-site scripting (XSS) vulnerability in search.php in eSyndiCat Portal System allows remote attackers to inject arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
RedBLoG 0.5 - '/admin/config.php?root_path' Remote File Inclusion
CVE-2006-5021CRITICALwebappsphp19 sep 2006
Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP
48RIESGO
abrir
Exploit-DBVexDay Proof
Innovate Portal 2.0 - 'index.php' Cross-Site Scripting
CVE-2006-4915webappsphp19 sep 2006
Cross-site scripting (XSS) vulnerability in index.php in Innovate Portal 2.0 allows remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
RedBLoG 0.5 - 'imgen.php?Root' Remote File Inclusion
CVE-2006-5021CRITICALwebappsphp19 sep 2006
Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP
48RIESGO
abrir
Exploit-DBVexDay Proof
RedBLoG 0.5 - '/admin/index.php?root_path' Remote File Inclusion
CVE-2006-5021CRITICALwebappsphp19 sep 2006
Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP
48RIESGO
abrir
Exploit-DBVexDay Proof
RedBLoG 0.5 - 'common.php?root_path' Remote File Inclusion
CVE-2006-5021CRITICALwebappsphp19 sep 2006
Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP
48RIESGO
abrir
Exploit-DBVexDay Proof
EShoppingPro 1.0 - 'Search_Run.asp' SQL Injection
CVE-2006-4871webappsasp18 sep 2006
SQL injection vulnerability in search_run.asp in Keyvan1 (aka Keyvan Janghorbani) EShoppingPro 1.0 allows remote attacke
23RIESGO
abrir
Exploit-DBVexDay Proof
PT News 1.7.8 - 'search.php' Cross-Site Scripting
CVE-2006-4917webappsphp18 sep 2006
Cross-site scripting (XSS) vulnerability in search.php in PT News 1.7.8 allows remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DBVexDay Proof
NixieAffiliate 1.9 - 'lostpassword.php' Cross-Site Scripting
CVE-2006-4894webappsphp18 sep 2006
Cross-site scripting (XSS) vulnerability in forms/lostpassword.php in iDevSpot NixieAffiliate 1.9 and earlier allows rem
23RIESGO
abrir
Exploit-DBVexDay Proof
ECardPro 2.0 - 'search.asp' SQL Injection
CVE-2006-4872webappsasp18 sep 2006
SQL injection vulnerability in search.asp in Keyvan1 (aka Keyvan Janghorbani) ECardPro 2.0 allows remote attackers to ex
23RIESGO
abrir
Exploit-DBVexDay Proof
Charon Cart 3.0 - 'Review.asp' SQL Injection
CVE-2006-4882webappsasp17 sep 2006
SQL injection vulnerability in Review.asp in Julian Roberts Charon Cart 3 allows remote attackers to execute arbitrary S
23RIESGO
abrir
Exploit-DBVexDay Proof
DotNetNuke 4.0 - HTML Injection
CVE-2006-4973webappsasp17 sep 2006
Cross-site scripting (XSS) vulnerability in Default.aspx in Perpetual Motion Interactive Systems DotNetNuke before 3.3.5
23RIESGO
abrir
Exploit-DBVexDay Proof
Zix Forum 1.12 - 'RepId' SQL Injection (2)
CVE-2006-4612webappsphp17 sep 2006
SQL injection vulnerability in ReplyNew.asp in ZIXForum 1.12 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
Exploit-DBVexDay Proof
Hitweb 3.0 - 'REP_CLASS' Multiple Remote File Inclusions
CVE-2006-4848webappsphp16 sep 2006
Multiple PHP remote file inclusion vulnerabilities in Brian Fraval Hitweb 3.0 allow remote attackers to execute arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP-post Web Forum 0.x.1.0 - 'profile.php' Multiple SQL Injections
CVE-2006-4877webappsphp16 sep 2006
Variable overwrite vulnerability in David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to overwrite a
23RIESGO
abrir
Exploit-DBVexDay Proof
phpQuiz 0.1.2 - SQL Injection / Code Execution
CVE-2006-4865webappsphp16 sep 2006
Walter Beschmout PhpQuiz allows remote attackers to obtain sensitive information via a direct request to cfgphpquiz/inst
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP-post Web Forum 0.x.1.0 - 'pm.php?replyuser' Cross-Site Scripting
CVE-2006-4881webappsphp16 sep 2006
Multiple cross-site scripting (XSS) vulnerabilities in David Bennett PHP-Post (PHPp) 1.0 and earlier allow remote attack
23RIESGO
abrir
Exploit-DBVexDay Proof
phpMyAdmin 2.x - 'db_operations.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-6942webappsphp15 sep 2006
Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
Jupiter CMS 1.1.4/1.1.5 - modules/register Multiple SQL Injections
CVE-2006-4876webappsphp15 sep 2006
Multiple SQL injection vulnerabilities in Jupiter CMS allow remote attackers to execute arbitrary SQL commands via (1) t
23RIESGO
abrir
Exploit-DBVexDay Proof
phpMyAdmin 2.x - Multiple Script Array Handling Full Path Disclosures
CVE-2006-6943webappsphp15 sep 2006
PhpMyAdmin before 2.9.1.1 allows remote attackers to obtain the full server path via direct requests to (a) scripts/chec
23RIESGO
abrir
Exploit-DBVexDay Proof
Jupiter CMS 1.1.4/1.1.5 - 'galleryuploadfunction.php' Arbitrary File Upload
CVE-2006-4875webappsphp15 sep 2006
Unrestricted file upload vulnerability in modules/galleryuploadfunction.php in Jupiter CMS allows remote attackers to up
23RIESGO
abrir
anteriorpágina 398 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.